Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. undici
  4. ›
  5. CVE-2026-85014

CVE-2026-85014: undici vulnerable to Denial of Service via WebSocketStream unclean close

September 29, 2026

undici’s WebSocketStream crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls abort() on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with a TypeError, and the handler discards that promise. The unobserved rejection surfaces as an unhandledRejection and, under Node.js’s default behavior, terminates the process.

A malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the WebSocketStream API and writing through a writer, which is the standard way to write.

All releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0.

References

  • cna.openjsf.org/security-advisories.html
  • github.com/advisories/GHSA-rx4f-c7p8-82vq
  • github.com/nodejs/undici/commit/1858656ebb1e919311c1f31613dfd581b7214349
  • github.com/nodejs/undici/commit/662d0ea671fe64139e79533c913fce412765e1d7
  • github.com/nodejs/undici/releases/tag/v7.29.1
  • github.com/nodejs/undici/releases/tag/v8.10.2
  • github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
  • nvd.nist.gov/vuln/detail/CVE-2026-85014

Code Behaviors & Features

Detect and mitigate CVE-2026-85014 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 7.0.0 before 7.29.1, all versions starting from 8.0.0 before 8.10.2

Fixed versions

  • 7.29.1
  • 8.10.2

Solution

Upgrade to versions 7.29.1, 8.10.2 or above.

Impact 5.9 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-248: Uncaught Exception
  • CWE-754: Improper Check for Unusual or Exceptional Conditions

Source file

npm/undici/CVE-2026-85014.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 30 Sep 2026 12:17:17 +0000.